cancel
Showing results for 
Search instead for 
Did you mean: 

LDAP synchronization with two Active Directory servers

bbiais
Champ in-the-making
Champ in-the-making
Hello,

I am working on the ldap synchronization of users and groups between Alfresco and Active Directory.

I need to synchronize <strong>two AD</strong> located on <strong>two different servers</strong>: AD1 and AD2.

-AD1 contains groups and users relative to company customers.
-AD2 contains groups and users relative to company employees.

I relied on the following page to create two synchronization modules:
http://docs.alfresco.com/4.2/index.jsp?topic=%2Fcom.alfresco.enterprise.doc%2Ftasks%2Fauth-example-t...

-Module ldap1 for AD1.
-Module ldap2 for AD2.

After performing some tests, users and groups sync works between Alfresco and both AD.

However, I wonder if it's possible to use <strong>only one</strong> ldap synchronization system (ex:ldap1) to connect two AD servers with Alfresco

Is it possible to base on the <strong>trust relationship</strong> between the two AD?

Thank you in advance.
1 REPLY 1

afaust
Legendary Innovator
Legendary Innovator
Hello,

yes, you can serve multiple domains from different ADs with one configuration if a) a trust relationship exists between the ADs (for authentication) and b) you have at least one directory that serves all the user / group information.

We had a customer once with 4 main ADs / domains for different regions of the world. They had a trust relationship between the domain controllers for authentication and synchronized local directory structures into one central directory with one root tree that we used to run our LDAP synchronization against.

Regards
Axel